Intrusion Detection Based on Unsupervised Clustering Algorithm

王飞,钱玉文,王执铨
DOI: https://doi.org/10.3969/j.issn.1005-9830.2009.03.003
2009-01-01
Abstract:An unsupervised clustering algorithm is proposed to solve the problem that most of intrusion detections based on clustering algorithm have artificial parameters.This method has no artificial parameter and is not affected by the order of data entrance.The shape of clusters is arbitrary,which can reflect the real distribution of data.By comparing the distances between unlabeled training data,the algorithm merges characters of clusters according to the characters of nearest samples.When each step of clustering is completed,the algorithm identifies the intrusion clusters by comparing the distances of clusters and calculating the rate of samples of each cluster among all samples.The identified clusters can be used in real data detection.The experimental result shows that the detection rate is 89.5% and the false alarm rate is 0.4% in detecting unknown intrusion.
What problem does this paper attempt to address?